TL;DR

Cisco SD-WAN systems are under active exploitation by malicious actors using multiple vulnerabilities. Immediate actions recommended include inventorying affected systems, applying patches, and enhancing security controls.

What happened

['Malicious cyber actors targeting Cisco SD-WAN', 'Exploitation of CVE-2026-20127 for initial access', 'CVE-2022-20775 used to escalate privileges']

Why it matters for ops

['Critical vulnerabilities in widely-used Cisco SD-WAN systems', 'Ongoing exploitation reported globally', 'Need for immediate remediation and security hardening']

Mitigation

  • Inventory all Cisco SD-WAN systems
  • Apply necessary patches immediately
  • Enhance security controls as per guidance

Action items

  • Implement firewall rules to isolate SD-WAN interfaces
  • Update system firmware and software to latest versions
  • Enable logging to remote syslog server

Detection IOCs

  • Authentication bypass attempts
  • Unusual network traffic patterns

Source link

https://www.cisa.gov/news-events/alerts/2026/02/25/cisa-and-partners-release-guidance-ongoing-global-exploitation-cisco-sd-wan-systems